ai is vulnerable to Denial of Service (DoS)
50
Medium Risk
Affected versions of this package are vulnerable to an unbounded download denial-of-service (DoS) issue where large or uncontrolled downloads can exhaust resources and potentially crash or hang applications. The underlying problem occurs when the SDK does not properly limit the size of downloads, allowing adversarial or unexpectedly large content to be fetched without safeguards. This can result in excessive memory or CPU usage and degraded availability for applications using the AI toolkit. The vulnerability is fixed by introducing bounds and safeguards on download operations to prevent unbounded resource consumption during file retrieval and processing.
You are affected if you are using a version that falls within the vulnerable range.
ai is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 6.0.83.
Upgrade the ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant